Re: need a suggestion of tool for pentest web application.
[email protected] Tue, 5 Jul 2005 10:01:12 -0600
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <OF3CDA275E.0B8DE58C-ON06257035.00572873-06257035.00580089@sasktel.sk.ca> |
I gather you are looking for a web vulnerability scanner. You can do a reasonable job with the freeware nikto (http://www.cirt.net/code/nikto.shtml). If you need to have a commercial product or want the better reporting you get from the commercial products, I am partial to AppScan (http://www.watchfire.com/products/security/default.aspx) or WebInspect (http://www.spidynamics.com/products/webinspect/index.html). WebInspect is the incumbent in the market. AppScan is an up and comer that is making good progress into the market. In my opinion AppScan has better reporting than WebInspect including very good compliance reporting. Rick Rick Wanner, B.Sc., I.S.P. GSEC, GCFW, GCIH, GHTQ, GREM Technical Analyst, Systems Security Sasktel Tel: 306-777-4832 Cell: 306-533-1812 Email: [email protected] Text Messaging: [email protected] "Pepin, Dany" <[email protected]> Sent by: [email protected] 06/28/2005 09:46 AM Please respond to "Intrusions List \(GCIA Practicals\)" <[email protected]> To <[email protected]> cc Subject [Intrusions] need a suggestion of tool for pentest web application. Hello list, Anyone can suggest me a tools to do a pentest on web application like intranet etc and tell me why this tool is nice. If possible with a license "per engagement". Thx in advance. Sorry for my bad English. Dany _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions NOTICE: This confidential e-mail message is only for the intended recipient(s). If you are not the intended recipient, be advised that disclosing, copying, distributing, or any other use of this message, is strictly prohibited. In such case, please destroy this message and notify the sender. _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions